Buffer Underwrite Vulnerability in OP-TEE OS by Linaro
CVE-2026-71969
What is CVE-2026-71969?
The OP-TEE OS, up to version 4.10.0, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations. This flaw resides within the mbedTLS software backend and the SE050 hardware driver. An attacker exploiting this vulnerability can provide input lengths that exceed the RSA modulus size, leading to heap memory corruption in the secure world. Specifically, when the source length surpasses the RSA length, it causes the subtraction operation to wrap into a large unsigned value, allowing the memcpy function to overwrite secure memory with attacker-controlled data. Prompt action is advised to mitigate potential security risks.
Affected Version(s)
optee_os 0 <= 4.10.0
optee_os 0 <= 4.10.0
optee_os 7b8b494e0a324cefec8ed386b7de413b44f1aaf3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
